Youstin (@iustinbb) 's Twitter Profile
Youstin

@iustinbb

Bug Bounty
youst.in
hackerone.com/youstin

ID: 1255163429746348038

calendar_today28-04-2020 15:54:20

58 Tweet

4,4K Followers

326 Following

d0nut 🦀 (@d0nutptr) 's Twitter Profile Photo

Had a blast working on a project last night with Youstin We ended up taking an existing bug bounty tool and building a version in rust that was over 20x faster Old (py): 2m15s New (rust): 6s

HolyBugx (@holybugx) 's Twitter Profile Photo

Found a 0day on a famous third-party vendor in a collaboration with Youstin and bend theory. Fair enough, the old versions are secure, new versions are affected. More info after vendor patch.

Found a 0day on a famous third-party vendor in a collaboration with <a href="/iustinBB/">Youstin</a> and <a href="/bendtheory/">bend theory</a>.

Fair enough, the old versions are secure, new versions are affected. More info after vendor patch.
d0nut 🦀 (@d0nutptr) 's Twitter Profile Photo

Introducing ripgen - A rust-based version of the popular dnsgen python utility by myself and Youstin. crates.io/search?q=ripgen github.com/resyncgg/ripgen

d0nut 🦀 (@d0nutptr) 's Twitter Profile Photo

It was fairly difficult getting back into writing, but with the help of a couple of awesome reviewers I've finally released my latest blog post: Eliminating Authorization Vulnerabilities with Dacquiri d0nut.medium.com/eliminating-au…

Corben Leo (@hacker_) 's Twitter Profile Photo

1/ First, let's talk background: How does ASP[.]NET get its configuration settings? (Like database connections) In the documentation: By default, it's "configured to read from `appsettings.json`, environment variables" and more. It gives an example that shows

James Kettle (@albinowax) 's Twitter Profile Photo

Thanks to everyone who attended Browser-Powered Desync Attacks, hope you enjoyed it! If you missed it but you're in the area, I'll be doing a repeat at 15:30 on Friday at #DEFCON. You can find the whitepaper, slides, code and labs at portswigger.net/research/brows…

Youstin (@iustinbb) 's Twitter Profile Photo

If anyone needs to extract regex patterns from a list of urls, I wrote a tool for it. github.com/iustin24/rextr… It's pretty fast and also supports PCRE.

Youstin (@iustinbb) 's Twitter Profile Photo

I'm excited to release the first version of a context-discovery tool I've been working on. github.com/iustin24/chame… - Chameleon can automatically detect the technologies running on a host and adapt to a calibrated wordlist. youst.in/posts/context-…

Omer Gil (@omer_gil) 's Twitter Profile Photo

New research: How we abused repository webhooks to access internal CI systems at scale. cidersecurity.io/blog/research/… 1/

Sam Curry (@samwcyo) 's Twitter Profile Photo

New blog post detailing some findings from auditing the Next.js ecosystem: "Exploiting Web3's Hidden Attack Surface: Universal XSS on Netlify's Next.js Library" Huge thanks to shubs and Brett Buerhaus for helping explore this! samcurry.net/universal-xss-…

d0nut 🦀 (@d0nutptr) 's Twitter Profile Photo

Hey! You! Yea, you! Does the idea of protecting billions of assets seem interesting? Are you a junior to mid-level #AppSec engineer that knows how to code? Are you authorized to work in the United States? Then you sound like a perfect fit for Robinhood's Appsec team! #Hiring

Hey! You!

Yea, you!

Does the idea of protecting billions of assets seem interesting? Are you a junior to mid-level #AppSec engineer that knows how to code? Are you authorized to work in the United States?

Then you sound like a perfect fit for Robinhood's Appsec team!

#Hiring
Youstin (@iustinbb) 's Twitter Profile Photo

Chameleon v1.1.0 is now live with new features 🎉 - JSON output - Fuzz using multiple HTTP methods - Save output to a file - Minor bug fixes github.com/iustin24/chame…

Youstin (@iustinbb) 's Twitter Profile Photo

If you want to find domains associated to an organization, you can explore DuckDuckGo's tracker-radar. It's a publicly accesible dataset that stores web tracking information, including domains operated by an organization. github.com/duckduckgo/tra…

If you want to find domains associated to an organization, you can explore DuckDuckGo's tracker-radar. 
It's a publicly accesible dataset that stores web tracking information, including domains operated by an organization.
github.com/duckduckgo/tra…
CMD - Constantin (@cmd_0_0) 's Twitter Profile Photo

It's finished! First LHE in Romania organised by Superbet Romania! We have the winners, congrats Youstin & nytr0gen 😍 Also a big thank you for all the participants! See you next year! Thank you HackerOne for helping us organising the event #BugBounty #hackerone

It's finished! First LHE in Romania organised by <a href="/SuperbetRomania/">Superbet Romania</a>! We have the winners, congrats <a href="/iustinBB/">Youstin</a> &amp; <a href="/nytr0gen_/">nytr0gen</a>  😍 Also a big thank you for all the participants! See you next year! Thank you <a href="/Hacker0x01/">HackerOne</a> for helping us organising the event #BugBounty  #hackerone
Youstin (@iustinbb) 's Twitter Profile Photo

I’m happy to have won first place together with nytr0gen at Superbet’s LHE. Defcamp was awesome, I’m really looking forward to next year’s event. Also shoutout to CMD - Constantin for organizing the LHE🎉

I’m happy to have won first place together with <a href="/nytr0gen_/">nytr0gen</a> at Superbet’s LHE. 
Defcamp was awesome, I’m really looking forward to next year’s event. 
Also shoutout to <a href="/CMD_0_0/">CMD - Constantin</a> for organizing the LHE🎉